Redhat Struts vulnerabilities
2 known vulnerabilities affecting redhat/struts.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-3834HIGHCVSS 7.5vall versions under 1.3.10_12019-10-03
CVE-2019-3834 [HIGH] CWE-470 CVE-2019-3834: It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON)
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase
cvelistv5
CVE-2014-0114HIGHCVSS 7.5PoCvall versions under 1.3.10_12014-04-30
CVE-2014-0114 [HIGH] CWE-20 CVE-2014-0114: Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x thr
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the pass
nvd